Comment on 6 digit OTP for Two Factor Auth (2FA) is brute-forceable in 3 daysparentComments−rrrrrrrrrrrryan4yIf there's a leak of valid usernames or email addresses, for a system that has a few million users, that has a lockout after 10 wrong guesses, then you could gain access to one account for every 10,000 lockouts.−seba_dos14yleak of valid usernames or email addresses...and passwords, because OTP is the second factor.
Comments
If there's a leak of valid usernames or email addresses, for a system that has a few million users, that has a lockout after 10 wrong guesses, then you could gain access to one account for every 10,000 lockouts.
...and passwords, because OTP is the second factor.